Pith. sign in

Paper Citation Record · LEDGER

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization

As of 8 August 2026, this Paper Citation Record lists 20 of 20 outbound references and 0 inbound Pith citation observations for arXiv:2607.18622.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.18622 v2

Coverage vector

measured 20 of 20 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-03T01:56:59.274728Z

measured 20 of 20 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

20 of 20 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved18
  • parse uncertain0
  • malformed identifier2
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d190f417-d402-481d-9572-87cb55831802 · outbound

This paper cites Query- based adversarial prompt generation.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Query- based adversarial prompt generation

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.447334Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.447334Z digest=sha256:dce66b7fa696dade40d927f12bf2df0c89ef76760ee348b3e9e53d6feb9d0de5

Observation 80d543ce-a7cf-4d4a-87ae-9f896c9f3eb3 · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.562647Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.562647Z digest=sha256:b65b4b71a04446a2a86a33a44e681123c564669d259efd45482911723ecc5940

Observation b86d549a-b4ad-470b-944e-d3a7316805d3 · outbound

This paper cites Attention tracker: Detecting prompt injection attacks in llms.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Attention tracker: Detecting prompt injection attacks in llms

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.643584Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.643584Z digest=sha256:71f29de51a7082909b1ec46f42ed86a182839717c9cbd89c4e65129f801188d0

Observation 3501e32d-a96c-4b6a-a0a4-4e0fefef94f1 · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.779480Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.779480Z digest=sha256:3d1b0a7ade0608a5c23ff393f31a6bad4c1fa18a971f74d8e6f4fa9955a41d68

Observation 19ea5d7d-369c-41fb-a598-312101913ad9 · outbound

This paper cites Pubmedqa: A dataset for biomedical research question answering.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Pubmedqa: A dataset for biomedical research question answering

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.853340Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.853340Z digest=sha256:f22c40adfd9104d48094a8498f60d02f4a47a470d3203095205b49d79f551546

Observation d38109ac-5807-47a6-87d7-53d253a4dca3 · outbound

This paper cites Instruction boundary: Quantifying biases in llm reasoning under various coverage.arXiv preprint arXiv:2509.20278,.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Instruction boundary: Quantifying biases in llm reasoning under various coverage.arXiv preprint arXiv:2509.20278,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.972654Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.972654Z digest=sha256:a0dc7d738c5c008e137fc4dd5257a97eb44270c507540682c5d83b89ca2fea30

Observation 5c7fa244-e9a5-4b67-a8fe-9d9116eea9da · outbound

This paper cites Tree of attacks: Jailbreaking black-box llms automatically.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Tree of attacks: Jailbreaking black-box llms automatically

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.065795Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.065795Z digest=sha256:ecc14fa5c9a3d64022f09a60ffb5c212f4290a08dd04050719791550ac8b2ad3

Observation abc6bdd9-fa6d-4439-9573-ffd07e8ee868 · outbound

This paper cites Granite Guardian.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Granite Guardian

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.170447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.170447Z digest=sha256:8b8ec7717ae35631cdcd0ae9ec90ccc02b19381cb9f7e4be9eafebdbd6b6ed92

Observation bcf92fe2-d32a-46de-a81d-f63e803f28b0 · outbound

This paper cites an unresolved cited work.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Unresolved cited work

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.277806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.277806Z digest=sha256:a633fcc5c4cf6b750656545944ccc2ff149a8e4921020e68d3b4a3fc29c191f8

Observation 54c0e337-67a5-4452-8931-222af3d5dcea · outbound

This paper cites Cats Confuse Reasoning LLM: Query Agnostic Adversarial Triggers for Reasoning Models.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Cats Confuse Reasoning LLM: Query Agnostic Adversarial Triggers for Reasoning Models

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.553796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.553796Z digest=sha256:453058296f7c87471c9a7619dc03727b0b7b2bc05510fe6f1b114749470a8979

Observation 9e597876-3897-42da-9cf1-594c97327fea · outbound

This paper cites LiveBench: A Challenging, Contamination-Limited LLM Benchmark.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization LiveBench: A Challenging, Contamination-Limited LLM Benchmark

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.763709Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.763709Z digest=sha256:0dac58b645176d49e8f1961dcb57d2f03eed26484a9bbea998eb24d3c305e3a6

Observation c0eb748f-b430-4ab7-8cd1-cce3180d2e47 · outbound

This paper cites Black-box optimization of llm outputs by asking for directions.arXiv preprint arXiv:2510.16794,.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Black-box optimization of llm outputs by asking for directions.arXiv preprint arXiv:2510.16794,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.893921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.893921Z digest=sha256:14bfed58a2cd5e504ff92777260b27a5e9ccd30a609883088a68b0db94d97a2c

Observation 97eef707-615d-401b-a73e-58e2ffbae2cb · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.999868Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.999868Z digest=sha256:2d572fcf8998dcc4e2a91898b93b3513b7f5448ca59b1c84e16ea0fc9abdcf55

Observation e7ca6615-69b6-4fa1-a270-9e4f1e036bea · outbound

This paper cites ,L(r) u o nu ! ,n u =max (1, round(λu)).

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization ,L(r) u o nu ! ,n u =max (1, round(λu))

Reference 19

Resolution
malformed identifier
no resolver link, observed 2026-08-03T01:56:59.163517Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:59.163517Z digest=sha256:3dd86a5590daa3dc5efde1c2fe1adaf590bd93a8e52fdd15cc7bb74193efc4d2

Observation 770b62f9-b048-4541-8acc-276f0a246960 · outbound

This paper cites CPInj achieves the highest Target ASR while maintaining perfect format compliance.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization CPInj achieves the highest Target ASR while maintaining perfect format compliance

Reference 20

Resolution
malformed identifier
no resolver link, observed 2026-08-03T01:56:59.274728Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:59.274728Z digest=sha256:76f84ec839bb13a0442c3f8fadd7d9af51de5ceaf6022424187d77b152abc5a1

Observation dd902880-98df-4544-b3eb-4b03dcac666c · outbound

This paper cites AdvPrompter: Fast Adaptive Adversarial Prompting for LLMs.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization AdvPrompter: Fast Adaptive Adversarial Prompting for LLMs

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:58.444116Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:58.444116Z digest=sha256:da460548def26b48431b21599546de4567c7dd1f9d735e4cc810e8a589aa378d

Observation 266ef3f7-791e-4b9d-9e96-ed75a01509e0 · outbound

This paper cites Can textual gradient work in federated learning? InThe Thirteenth International Conference on Learning Representations, 2025a.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Can textual gradient work in federated learning? InThe Thirteenth International Conference on Learning Representations, 2025a

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.302491Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.302491Z digest=sha256:f2a4aed42f79aa52c865305c7ae1becbf665dba71fdeb7b573e74cd6f67b2eca

Observation b7a804f1-e460-4a19-8d8d-6b18ea3ec16c · outbound

This paper cites Folio: Natural language reasoning with first-order logic.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Folio: Natural language reasoning with first-order logic

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.378176Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.378176Z digest=sha256:a42dbcc0eca66de58ae7c0feaedaff3ea1ef564159a7684cf811640bbfe43fb6

Observation d25f5654-317f-419d-969b-08a285c3e634 · outbound

This paper cites Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Llama Guard: LLM-based Input-Output Safeguard for Human-AI Conversations

Reference 2025

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.704085Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.704085Z digest=sha256:2197044da7cc2f2c27b75e7ca02ce0d4b32b958a67e0e51ad4f815c121de69e1

Observation 3e37472e-aaf8-46c9-a9af-a051b615573b · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-03T01:56:57.266792Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T01:56:57.266792Z digest=sha256:f7bd7a1ed8bbdae56c68a75a9a11c43e7df97f5bd0aa185875ac4fafbbb52ea3

Pith citing papers

No inbound Pith citation observations are available.